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Description of Information 


Classification/Markings 


Reason 


Declass 


Remarks 


A. (U) GENERAL 










1 . (U) The fact that NS A/CSS or 
TAO performs computer 
network exploitation (CNE) 


UNCLASSIFIED 


N/A 


N/A 


(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 


2. (S//REL) The fact that 

NSA/CSS or TAO, as part of 
CNE operations, performs 
remote subversion 


SECRET//REL TO USA, 
FVEY 


Sec 1.4(c) 


*25 years 


(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level 
and/or require 
compartmentation . 

(U) Foreign releasability 
decisions on specific details 
relating to remote subversion 
are handled on a case-by-case 
basis. Contact TAO CAO for 
further guidance. 


3. (S//SI//REL) Identification of 
specific remote subversion 
methods used by NSA/CSS or 
TAO, to include: 

- Endpoint access, exploitation, 
or operations 

- On-net access, exploitation, or 
operations 

- Software implant access, 
exploitation, or operations 

- Accessing or exploiting data 
at rest 


SECRET//SI//REL TO USA, 
FVEY 


Sec 1.4(c) 


*25 years 


(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level 
and/or require 
compartmentation . 

(U) Foreign releasability 
decisions on specific details 
relating to remote subversion 
are handled on a case-by-case 
basis. Contact TAO CAO for 
further guidance. 


4. (S//SI//REL) The fact that 
NSA/CSS or TAO, as part of 
CNE operations, performs 
physical subversion, to include: 


SECRET//SI//REL TO USA, 
FVEY 


Sec 1.4(c) 


*25 years 


(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification and 
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- Close access enabling, 
exploitation, or operations 

- Off-net enabling, exploitation, 
or operations 

- Supply chain enabling, 
exploitation, or intervention 
operations 

- Hardware implant enabling, 
exploitation, or operations 








require ECI protection. 

(U) Foreign relcasability 
decisions on specific details 
relating to physical 
subversion arc handled on a 
case-by-case basis. Contact 
TAO CAO for further 
guidance. 


5 . ( U) The association of any 

specific BCI name or tngraph, 
with NS A/CSS, EC1, S1GINT, 
or intelligence 


UNCLASSIFIED. 'TOR 
OFFICIAL USE ONLY 


FOIA 3 


N/A 




6. (U) *I*hc association ot a 

specific TAO BCI name or 
tngraph with CNE and/or TAO 


CONF1DENT1AU/REL TO 
USA. FVEY 


See. 1 .4(c) 


N/A 




7. (U) ITic fact that a specific 
individual is cleared for a 
specific TAO BCI, when there 
is no association betw een the 
BCI and TAO 


U N C LASS I FIED/T’OR 
OFFICIAL USE ONLY 






(U) If the details of the 
association reveal the fact 
that the ECI is TAO’s, then it 
would be 

CONFIDENTIAL REL TO 
USA. FVEY. in accordance 
with er.tr>- 5. 


8. (U) The fact that NSA/CSS or 
TAO conducts CNE for foreign 
intelligence collection. 


UNCLASSIFIED 


N/A 


N/A 




9. (U) The fact that NSA/CSS or 
TAO, as part of CNE 
operations, performs CNE to 
support U.S. Government CNA 
efforts 


UNCLASSIFIED 


N/A 


N/A 


(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 


10. (U) The fact that NSA/CSS or 
TAO, as part of CNE 
operations, trains, equips, and 
organizes the U.S. Cryptologic 
System to support the CNE, 
CNA, and CND requirements 
needs of its customers 


UNCLASSIFIED 


N/A 


N/A 


(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 


1 1 . (U) The fact that NSA/CSS or 
TAO, as part of CNE 
operations, provides CNO- 
related military targeting 
support 


UNCLASSIFIED 


N/A 


N/A 


(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 


12. (U) The fact that NSA/CSS or 
TAO, as part of CNE 
operations, provides 
intelligence gam/loss 
assessments in response to 
Combatant Commander 
(COCOM) CNO targeting 


UNCLASSIFIED 


N/A 


N/A 


(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 


13. (U) The fact that NSA/CSS or 
TAO, as part of CNE 
operations, develops and 
supports analytic modeling and 
simulation techniques to 
support CNECNA efforts 


UNCLASSIFIED 


N/A 


N/A 


(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 
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14. (U) The fact that NSA/CSS or 
TAO, as part of CNE 
operations, targets, collects and 
processes computers, computer 
networks and computer-to- 
computer (C2C) 
communications without 
reference to a specific 
operation, activity or target 


UNCLASSIFIED 


N/A 


S/A 


(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 


15. (S//S1//REL) The fact that NSA 
or TAO, as part of CNE 
operations, targets, collects and 
processes specific computer 
protocols (such as email, instant 
messaging, file transfer 
protocols) 


SECRET//S1//REL TO USA. 
FVEY 


Sec 1.4(c) 


♦25 years 


(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level 
to TOP SECRET. 

(U) Details may also be 
protected by one or more 
ECls and or a different level 
of foreign rcleasability 
(including NOFORN). 


16. (S//S1//REL) The fact that 
NSA/CSS or TAO, as part of 
CNE operations, remotely 
introduces code into target 
computer networks to facilitate 
foreign intelligence collection 


SECRET/, ^L’/REL TO USA. 
FVEY 


Sec 1.4(c) 


♦25 years 


(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level 
to TOP SECRET. 

(U) Details may also be 
protected by one or more 
ECls and'or a different level 
of foreign releasabilitv 
(including NOFORN). 


17. (TS//S1//REL) The fact that 
NSA/CSS or TAO, as part of 
CNE operations, conducts off- 
net field operations to develop, 
deploy, exploit, or maintain 
intrusive access, w ithout further 
detail 


TOP SECRET//S1//REL TO 
USA, FVEY 


Sec 1.4(c) 


♦25 years 


(U) Details may also be 
protected by one or more 
ECls and'or a different level 
of foreign releasabilitv 
(including NOFORN). 


18. (S//S1//REL) The fact that 
NSA/CSS or TAO, as part of 
CNE operations, conducts off- 
net activities at specified 
locations other than NSA CSS 
facilities 


TOP SECRET//S1 

See remarks for foreign 
relcasability. 


Sec 1.4(c) 


♦25 years 


(U) Details may also be 
protected by an ECU 

(U) Foreign releasabilitv 
decisions handled on a casc- 
bv-casc basis. Contact TAO 
CAO for further guidance. 


19. (U) TAO project names, in 
association with CNE or TAO. 
with no amplifying details 


UNCLASSIFIED, /FOR 
OFFICIAL USE ONLY 


FOIA (3) 


S/A 




B. (U) PARTNERLNO/COLLABORATION 


20. (O/REL) The fact that 

NSA/CSS or TAO, as pan of 
CNE operations, collaborates 
with Second Party Partners to 
conduct CNE activities 


CONI IDEM lAL 'REL TO 
USA. FVEY 


Sec 1.4(c.d) 


♦25 years 


(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level. 

(U) Details may also be 
protected by one or more 
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ECls. 


21. (C//RHL) The fact that 

NSA/CSS or TAO, as part of 
CNE operations, collaborates 
with specific Second Party 
partners on specific ECls 


CONFIDENT1AL//REL TO 
USA, FVEY 
See remarks for foreign 
rclcasability. 






(U) Foreign rclcasability 
decisions handled on a case- 
by-case basis. Contact TAO 
CAO for further guidance. 


22. (C//REL) Details of the CNE 
collaboration between 
NSA/CSS or TAO and Second 
Party partners 


SECRET//S1 at a minimum 

See remarks for foreign 
rclcasability. 






(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level 
to TOP SECRET//SL 

(U) Details may also be 
protected bv one or more 
ECls. 

(U) Foreign rclcasability 
decisions handled on a case- 
by-case basis. Contact TAO 
CAO for further guidance. 


23. (S//REL) The fact that 
NSA/CSS or I AO. as part of 
CNE operations, collaborates 
with unspecified Third Party 
Partners in support and conduct 
of CNE activities 


SECRET//REL TO USA, 
FVEY 


See 1.4(c.d) 


♦25 years 


(U ) Details may also be 
protected by an EC1. Contact 
TAO CAO for further 
guidance. 


24. (S//REL) The fact that 

NSA/CSS or TAO, as part of 
CNE operations, collaborates 
with specified Third Party- 
Partners in support and conduct 
of CNE activities 


POP SECRET7/S1 

See remarks tor foreign 
rclcasability. 


Sec 1.4(c.d) 


♦25 years 


(U) Foreign rclcasability 
decisions handled on a case- 
by-case basis. Contact TAO 
CAO for further guidance. 

(U) Details may also be 
protected by an EG. Contact 
TAO CAO for further 
guidance. 


25. (U//FOUO) The fact that 
NSA/CSS or TAO, as part of 
CNE operations, collaborates 
with a specific US 
Govcmmcnt'IC entity 


UNCLASSIFIED,, FOR 
OFFICIAL USE ONLY 


FOIA (3) 


N/A 


(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level. 

(U) Details may also be 
protected by one or more 
ECls and'or a different level 
of foreign rclcasability 
(including NOFORN). 


26. (C7/REL) ITic fact that 

NSA/CSS or TAO, as part of 
CNE operations, collaborates 
with a specific US 
Govcmmcnt'IC entity on a 
specific EC1 


CONF1DENT1AL7REL TO 
USA, FVEY 


See. 1 4(c) 


♦25 years 


(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level. 

(U) Details may also be 
protected by one or more 
ECls and'or a different level 
of foreign releasability 
(including NOFORN). 
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C. (t ) T(K)1.S AND 1KCHMQLKS 



27. (U) The existence of CNE 
tools, with no further 
details context 


UNCLASSIFIED 


N/A 


N/A 




28. (U) Cover names of CNE tools, 
with no details/ccmtcxt 


UNCLASSIFIED 


N/A 


N/A 




29. (S//S1//REL) When associated 
with remote subversion, 
details.' descriptions concerning 
CNE tools, to include: 

- Specific type (ir. 
hardwarc/softwarc, etc.) 

- Purpose 

- Capabilities 

- Concealment Techniques 

- Electronic signatures 

- Combination s) of the above 


SECRET/, SI 
at a minimum 

See remarks tor foreign 
rcleasability. 


See. 1 .4(c) 


♦25 years 


(U) Details indicat i n l 
specific targets, level of 
success or capabilities may 
raise the classification level 
to TOP SECRET. 

(U) Details may also be 
protected by one or more 
ECls and/or a different level 
of foreign rcleasability 
(including NOFORN). 

(U) Foreign rcleasability 
decisions handled on a casc- 
bv-casc basis. Contact TAO 
CAO tor further guidance. 


3U. (S//S1//REL) When associated 
with physical subversion, 
dctailsdcscnptions concerning 
CNE tools, to include: 

- Specific type (ir. 
hardware software, etc.) 

- Purpose* 

- Capabilities 

- Concealment Techniques 

- Electronic signatures 

- Combination's) of the 

above 


TOP SECRET//S1 

See remarks for foreign 
rcleasability 


See 1.4(c) 


♦25 years 


(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level 
to TOP SECRET. 

(U) Details may also be 
protected by one or more 
ECls and'or a different level 
of foreign rcleasability 
(including NOFORN). 

(U) Foreign rcleasability 
decisions handled on a ease* 
bv-casc basis. Contact TAO 
CAO tor further guidance. 


31 . (U//FOUO) Technical details 
concerning specific software 
vulnerabilities, when publicly 
know n, and that arc exploited 
for CNE acti vines 


UNCLASSIFIED FOR 
OFFICIAL USE ONLY 


FOIA (3) 


N/A 




32. (S//S1//REL) Technical details 
concerning specific software 
vulnerabilities, when not 
publicly known, and that are 
exploited for CNE activities 


TOP SECRET//S1 
See remarks tor foreign 
rcleasability. 


See 1.4(c) 


♦25 years 


(U) Details may be protected 
as NOFORN on a casc-by- 
casc basis. 

(U) Some tools may be 
protected under an ECI 
and'or additional handling 
caveats. 

(U) Foreign rcleasability 
decisions handled on a casc- 
bv-casc basis. Contact TAO 
CAO tor further guidance. 
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| D. (f ) OPERATIONS and TARGETING 



33. (U) The fact that NSA/CSS or 
TAO, as part ofCNE 
operations, targets a specific 
country or international 
organization 


SECRET//SI//REL TO USA. 
FVEY at a minimum 


See. 1.4(c) 


♦25 years 


(U) Details may also be 
protected by a different level 
of foreign rcleasability 
(including NOFORN). 

(U) Contact TAO CAO for 
further guidance on levels of 
success as well as for more 
specific targeting details such 
as mdividual(s), specific 
government cntity(ics), etc. 


34. (S//S1//REL) Association ot‘ 
cover names tor off-net 
operations (ir., physical 
subversion activities) with 
amplifying details (e.g.. 
specific electronic components, 
systems, their host facilities, 
etc) 


TOP SECRET//S1 

See remarks for foreign 
rcleasability. 


See 1.4(c) 


♦25 years 


(U) Details may also be 
protected by one or more 
ECls. 

(U) Foreign rcleasability 
decisions handled on a case- 
by-case basis. Contact TAO 
CAO for further guidance. 


35. (S//REL) Association of cover 
names tor on-net operations 
(i.e.. remote subversion 
activities) with amplifying 
details (e.g., specific electronic 
components, systems, their host 
facilities, etc) 


SECRET//S1 at a minimum 

See remarks for foreign 
rcleasability. 


See 1.4(c) 


♦25 years 


(U) Details may also be 
protected by one or more 
ECls. 

(U) Foreign rcleasability 
decisions handled on a case- 
by-case basis. Contact TAO 
CAO tor further guidance. 


36. (S//S1//REL) Individual details 
of CNE activities, such as: 

- Target information including 
intended target network and/or 
device 

- Vulnerability being targeted 

- Target infrastructure 


TOP SECRET/VS1 

See remarks for foreign 
rcleasability. 


See 1.4(c) 


♦25 years 


(U) Details may also be 
protected by one or more 
ECls. 

(U) Foreign rcleasability 
decisions handled on a casc- 
by-casc basis. Contact TAO 
CAO for further guidance. 


37. (TS//S1//REL) The fact that 
NSA/CSS or TAO, as part of 
CNE operations, is attempting 
to exploit or has succeeded in 
exploiting a specific 
vulnerability (e.g.. in a firewall, 
operating system, software 
application, etc.), and a specific 
entity or f acility within a 
target’s nVeomputer structure 


TOP SECRET, VS1 

See remarks for foreign 
rcleasability. 


See 1.4(c) 


♦25 years 


(U) Details may also be 
protected by one or more 
EC1. 

(U) Foreign rcleasability 
decisions handled on a case- 
by-case basis. Contact TAO 
CAO tor further guidance. 


38. (S//S1//REL) Facts related to 
the description of U.S. 
hardware or software implants 
and location (c.g.. specific 
organization and Internet 
Protocol Device/Address, etc.) 
on a target’s 

IT'communications system 


TOP SECRET//S1 
See remarks for foreign 
rcleasability. 


See 1.4(c) 


♦25 years 


(U) Details may also be 
protected by one or more 
EC1. 

(U) Foreign rcleasability 
decisions handled on a case- 
bv-casc basis. Contact TAO 
CAO tor further guidance. 


39. (S.7S1//REL) Facts related to 
the exact timing, location. 


TOP SECRET, VS1 
at a minimum. 


Sec 1.4(c) 


♦25 years 


(IT) Details may also be 
protected by one or more 
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participants, off-net or on-net 
operations, CNE command, 
control and data exfiltration 
toolscapabilitics and locations, 
used to exploit or maintain 
intrusive access to a target’s 
IT ^computer structure 


See remarks for foreign 
rclcasability. 






EC1. 

(U) Foreign rclcasability 
decisions handled on a casc- 
by-casc basis. Contact TAO 
CAO for further guidance. 


40. (S//SL7REL) Combination of 
details of individual aspects of 
CNE activities, that would 
allow a specific target to take 
specific counter-measures, such 
as: 

- Specific target network or 
device smd 

- Specific capability, tool or 
technique used for exploitation 
of vulnerability 


TOP SECRET/VS 1 

See remarks tor foreign 
rcleasability. 


Sec 1.4(c) 


♦25 years 


(U) Details may also be 
protected by one or more 
EC1. 

(U) Foreign rclcasability 
decisions handled on a case- 
by-case basis. Contact TAO 
CAO for further guidance. 


41 . (TS//SL7REL) The fact that 
NSA/CSS (or TAO) acquires 
cry ptographic enabling 
information through CNE 
activities. 


TOP SECRET, /SI 

See remarks tor foreign 
rclcasability. 


Sec 1.4(c) 


♦25 years 


(U//FOUO) Details may also 
be protected by one or more 
EC1 andor HCS. 

(U) Foreign rclcasability 
decisions handled on a case- 
by-case basis. Contact TAO 
CAO for further guidance. 



(U) *25 years: Declassification in 25 years indicates that the information is classified tor 25 years from the date a 
document is created or 25 years from the date of this original classification decision, whichever is later. 



AC RON V MS/DEF1N 1 TIONS: 



(U) Computer Network exploitation (CNE): intelligence collection and enabling operations to gather data from 
target or adversary automated information systems (A1S) or networks. (Per DCID 7/3. Information Operations and 
Intelligence Community Related Activities, effective 01 July 1999. administratively changed 5 June 2003) 

(U) Computer Network Attack (CNA): operations to manipulate, disrupt, deny, degrade, or destroy information 
resident in computers and computer networks, or the computers and networks themselves. (Per DCID 7/3. Information 
Operations and Intelligence Community Related Activities, effective 01 July 1999. administratively changed 5 June 
2003) 

(U) Computer Network Defense (CND): efforts to defend against the CNO of others, especially that dimeted against 
U.S. and allied computers and networks. (Per DCID 7/3, Information Operations and Intelligence Community Related 
Activities, effective 01 July 1999, administratively changed 5 June 2003) 

(U) Computer Network Operations (CNO): CNE, CNA, and CND collectively. (Per DCID 7/3. Information 
Operations and Intelligence Community Related Activities, effective 01 July 1999. administratively changed 5 June 
2003) 

(U) Information Operations (IO): actions taken to affect adversary information and information systems while 
defending one’s own information and information systems. IO is an integrating strategy. (Per DCID 7/3, Information 
Operations and Intelligence Community Related Activities, effective 01 July 1999. administratively changed 5 June 
2003) 
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(S//SI//REL) Intrusive Access: Refers to CNE operations involving remote manipulation, hardwarc.'softw are 
modifications, or sensing of environment changes in a computer device or system, and/or occasionally the facilities that 
house the systems. 

(S//SI//REL) Off-Net Operations: Refers to covert or clandestine field activities of personnel carried out in support of 
CNE activities. 

(S//S1//REL) Physical subversion: Subverts with physical access to a device or host facility. Other terms sometimes 
used to connote physical subversion arc close access enabling, exploitation, or operations; off -net enabling, 
exploitation, or operations; supply-chain enabling, exploitation, or operauons: or hardware implant enabling, 
exploitation, or operations. 

(S//S1//REL) Remote subversion: Subverts without physical access to a device or host facility; obtains unauthorized 
permission. Other terms sometimes used to connote remote subversion arc computer network exploitation; endpoint 
access, exploitation, or operations: on-net access, exploitation, or operations; software implant access, exploitation, or 
operations; or accessing or exploiting data at rest. 

(SZ/Sl/VREL) Supply Chain Operations: Interdiction activities that focus on modifying equipment in a target’s supply 
chain. 
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